PRIVACY POLICY
Your evidence
stays yours.
What we collect, why we collect it, who can see it, and how long we keep it — in plain language.
Effective
1. Who we are
ParadoxAI is operated by Nixtre Technologies Ltd., a software company based in New York, NY, United States, which is the data controller for the personal data described here. For privacy questions, contact admin@nixtre.com or call +1 (315) 888-1082.
2. What we collect
Account details. Your name, email address, password (stored only as an irreversible hash), role, and whether your account is active.
Material you submit. Files, links, documents and text you send for analysis, along with anything derived from them — extracted text, transcripts, generated reports, and a fingerprint used to detect tampering.
Your conversations. Messages exchanged with the analyst, and the steps it took to answer.
Operational records. Sign-in events, usage counts against your quota, and administrative actions, kept so the Service can be run and audited securely.
If you contact us. Details you provide when requesting a demo, applying for a role, or asking for support.
3. Material about other people
Material you submit will often contain personal data about people who are not our users — faces, voices, names, locations. It may reveal sensitive characteristics such as health, beliefs, political opinions or sexuality.
You decide what to submit, and you are responsible for having a lawful basis to do so. We process that material only to perform the analysis you asked for. We do not use it to identify individuals, build profiles, or enrich it with data from other sources.
If you are asked to remove material about a specific person, tell us at admin@nixtre.com and we will act on it.
4. Why we use it, and on what basis
- To provide the Service — running analyses, storing your cases, producing reports. Basis: performance of our contract with you.
- To keep it secure and working — authentication, abuse prevention, quotas, diagnosing failures. Basis: our legitimate interest in a secure, reliable service.
- To communicate with you — service notices, invitations, and replies to your enquiries. Basis: contract, or legitimate interest.
- To meet legal obligations — accounting, and responding to lawful requests. Basis: legal obligation.
We do not sell personal data, do not use it for advertising, and do not use your material to train models made available to anyone else.
5. Who we share it with
We share personal data only with providers who process it on our behalf, for the purposes above. Each receives only what its step needs:
- Hostinger — Runs the Service on a virtual server located in the United States.
- Aiven — Managed database for accounts, case records and settings.
- Cloudflare (R2) — Private, encrypted storage for uploaded material and generated reports.
- Google (Gemini API) — Examines media and text, transcribes speech, and runs web searches for claim research.
- Brave Search — Web searches for claim research. Receives search terms, not files.
- NewsAPI — News searches for claim research. Receives search terms, not files.
- Resend — Delivers account, invitation and service emails.
- OpenAI — Backup speech transcription and web search, only where we enable it.
- Sentry — Error diagnostics, only where we enable it. Receives error types and code locations — never your material.
Analysis providers process material under their own terms, which can include keeping it for a limited period for abuse and security monitoring. We use them on terms under which they do not use your material to train their models. Files we upload to them are deleted when a step completes, or by the provider automatically soon after.
Social platforms (Facebook, Instagram and X) receive data only where you or your administrator has connected an account and a request arrives through it. We may also disclose data where legally required, or to establish or defend legal claims.
Administrators in your organisation can review cases, conversations and attachments belonging to their users. Those reviews are recorded.
6. International transfers
We are based in the United States, and our providers process data in the United States and in other countries where they operate. Where data leaves the UK or European Economic Area, we rely on an adequacy decision or on standard contractual clauses with appropriate safeguards. Contact us for a copy of the relevant mechanism.
7. How long we keep it
Cases, uploaded material and reports are kept until you or an administrator deletes them, or until your account is closed. When an account is deleted, its cases, conversations and files are removed.
A record of security-relevant actions — sign-ins, administrative changes, reviews of your material — is kept after an account is closed, so those events remain reviewable. It records what was done and by which account, not the material you submitted.
Deletion removes material from active systems. Our database provider’s backups are encrypted and replaced on a rolling schedule, so deleted data leaves them as older backups expire. A minimal record may be kept where needed to prevent a deleted item from being reprocessed, or to meet a legal obligation.
8. How we protect it
Access requires authentication, connections are encrypted in transit, passwords are stored only as irreversible hashes, and changing a password ends existing sessions. Access to cases is restricted to their owner and to administrators, whose reviews are recorded. No service can promise perfect security; if a breach affects your data we will notify you and any regulator as the law requires.
9. Your rights
Depending on where you live, you may have the right to access a copy of your data, correct it, delete it, restrict or object to how we use it, withdraw consent, and receive it in a portable form. You can exercise most of these in the product; for the rest, contact admin@nixtre.com.
We respond within the period the law allows. If you are unhappy with our response you can complain to your local data protection authority.
We do not make decisions about you by automated means that produce legal or similarly significant effects.
10. Cookies and local storage
We use only what is needed to run the Service: a token that keeps you signed in, and local preferences such as your last-used filter. We do not use analytics, advertising or cross-site tracking cookies.
11. Children
The Service is for professional use and is not directed at anyone under 18. We do not knowingly collect their personal data. If you believe a child has provided us data, contact admin@nixtre.com and we will delete it.
12. Changes to this policy
We will update this page when our practices change and revise the effective date above. If a change is material we will give notice before it takes effect. See also our Terms and Conditions.